package com.example.authorization.controller;

import org.springframework.security.access.prepost.PreAuthorize;
import org.springframework.security.core.Authentication;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;

@RestController
@RequestMapping("/demo")
public class DemoController {
    @GetMapping
    @PreAuthorize("hasRole('ROLE_USER')")
    public String demo() {
        return "hello demo";
    }

    @PostMapping("/me")
    public Authentication who(Authentication authentication) {
        return authentication;
    }


}
